NSE4 Firewall Policies and NAT Practice Question
What is the default action of the implicit deny policy at the end of the firewall policy list?
⚠ Common exam trap
A common mix-up: candidates confuse the implicit deny with the 'deny' action available in explicit policies, or mistakenly think that the implicit deny can be changed to 'allow' or 'monitor' to simplify troubleshooting, but FortiGate's design enforces a strict default-deny stance for unmatched traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deny
In FortiGate firewalls, the implicit deny policy at the end of the firewall policy list has a default action of 'Deny'. This means any traffic that does not match an explicit firewall policy is automatically dropped. This is a fundamental security principle to ensure that only explicitly permitted traffic is allowed through the firewall.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Monitor (log only)
Why it's wrong here
Monitor (log only) is incorrect because the implicit deny policy does more than just observe traffic; it actively drops packets that do not match any explicit policy. In FortiOS, the only way to log traffic without blocking it is to configure a policy with action set to ACCEPT and logging enabled, but the implicit deny is a fixed rule that silently discards unmatched traffic without generating a log by default, making it fundamentally different from a monitor or log-only action.
- ✗
Allow
Why it's wrong here
Allow is incorrect because the implicit deny policy is designed as a security fail-safe to block all traffic that has not been explicitly permitted. If the default action were to allow unmatched packets, the firewall would fail in its primary role of preventing unauthorized access, and any misconfiguration in the policy list would leave the network exposed. FortiOS enforces an implicit deny at the end of every policy lookup, ensuring that only explicitly allowed traffic passes.
- ✓
Deny
Why this is correct
Deny is correct because FortiOS includes an unmodifiable, last-resort implicit deny policy that drops any packet that does not match an explicit IPv4 or IPv6 firewall policy. This policy is evaluated only after all explicit policies have been checked and no match is found, meaning it effectively enforces a default-close security posture. It is not visible in the policy list, cannot be removed or reordered, and by default does not log, so administrators often create an explicit deny-all rule with logging to gain visibility into blocked traffic.
- ✗
Redirect to authentication
Why it's wrong here
Redirect to authentication is incorrect because the implicit deny policy does not involve any authentication or redirect mechanism; it simply drops the packet without any additional processing. Authentication redirects, such as captive portal or firewall authentication, are explicit features that must be configured on a matching policy, often with specific action settings and authentication profiles. The implicit deny operates at the lowest level, purely blocking unmatched traffic without interacting with user identity or portal services.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following is the default action of a FortiGate firewall policy if no policy matches the traffic?
easy- A.Log and drop
- B.Redirect to authentication
- C.Accept
- ✓ D.Deny
Why D: FortiGate firewall policies operate on a 'first-match' basis, and if no policy matches the traffic, the default action is to deny the traffic. This is a fundamental security principle to ensure that only explicitly permitted traffic is allowed through the firewall. The implicit deny rule is automatically applied at the end of the policy list and cannot be removed or modified.
Variation 2. Which of the following describes the implicit deny action in FortiGate firewall policies?
easy- A.A policy that is automatically created when the first policy is added
- B.A policy that denies traffic based on the source IP
- C.A policy that denies all traffic and can be moved to any position
- ✓ D.A default policy that denies all traffic unless explicitly allowed
Why D: In FortiGate firewall policies, the implicit deny is a default, system-generated rule that denies all traffic not explicitly permitted by any configured policy. It is always present at the end of the policy list and cannot be moved, modified, or deleted. This ensures that any traffic not matching an explicit 'accept' policy is automatically dropped, enforcing a default-deny security posture.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.